The Cyber Security Association of China (CSAC) on Friday released a detailed report exposing two major cases of cyberattacks allegedly orchestrated by U.S. intelligence agencies against critical Chinese industries, including military and defense-related enterprises. The revelations have sparked strong responses from both cybersecurity experts and the Chinese government, who have issued heightened security alerts for key sectors.
According to the report, the U.S. has intensified cyber espionage efforts in recent years, focusing on stealing sensitive military research and core production data from Chinese universities, research institutions, and enterprises. The CSAC described the operations as “targeted, covert, and strategically significant,” posing a grave threat to China’s national security.
High-Profile Attacks Detailed
One case cited in the report involved the exploitation of zero-day vulnerabilities in Microsoft Exchange email systems. From July 2022 to July 2023, U.S. intelligence agencies allegedly maintained long-term access to the email servers of a major Chinese military-industrial firm. By compromising the enterprise’s domain controller server, attackers gained deep access to more than 50 critical devices across the internal network.
The hackers are reported to have used proxy IPs from countries including Germany, Finland, South Korea, and Singapore to obscure their origin, launching over 40 attacks during the period. They allegedly exfiltrated sensitive data—including design blueprints and system parameters—by implanting malicious tools and establishing covert data channels, while evading detection through obfuscation techniques.
A second case occurred between July and November 2024, involving cyber intrusions into a communications and satellite internet enterprise. Attackers used proxy IPs from countries such as Romania and the Netherlands to exploit vulnerabilities in the company’s electronic file system. A memory-resident backdoor was implanted, followed by a data-stealing trojan delivered through the firm’s software update mechanism. Over 300 devices were reportedly compromised, and sensitive information tied to military networks was targeted using keyword searches like “military special network” and “core network.”
Foreign Ministry Responds
In a press briefing held Friday, Chinese Foreign Ministry spokesperson Guo Jiakun condemned the attacks as “further proof of the U.S. government’s malicious cyber operations against China.” Guo said the incidents exposed the “hypocrisy” of Washington, which frequently portrays itself as a victim of cyberattacks while actively engaging in offensive cyber operations.
“It is the latest evidence of the U.S. government’s malicious cyberattacks on China,” Guo stated. “It once again shows that the U.S. is the top cyber threat faced by China.”
Guo added that U.S. operations often leverage allied countries in Europe and neighboring regions, and emphasized that cybersecurity is a global issue requiring dialogue and cooperation rather than confrontation.
Expert Analysis and Warning
Li Yan, director of the Institute of Technology and Cybersecurity at the China Institutes of Contemporary International Relations, noted that China remains the world’s biggest victim of cyberattacks. “What we’re seeing now is only the tip of the iceberg,” Li said. “For years, the U.S. has maintained a globally aggressive posture in cyber operations, with highly organized attack units and state-level support structures.”
According to official statistics cited in the CSAC report, over 600 cyberattack incidents by state-sponsored advanced persistent threat (APT) groups have targeted Chinese institutions in 2024 alone—most of them allegedly linked to U.S. intelligence agencies. The report highlights the use of sophisticated attack infrastructure, including standardized tools, comprehensive engineering systems, and advanced vulnerability exploitation capabilities.
Strategic Implications
The targeted nature of the attacks, especially on defense-related enterprises and critical technologies, indicates strategic motivations, according to the CSAC. Both attacks showcased advanced concealment techniques, including deleting system logs, using trojans, and real-time monitoring of compromised devices, underscoring the attackers’ professional expertise.
The report has triggered renewed calls within China to enhance cybersecurity capabilities and improve system resilience in key sectors.
“National security is no trivial matter,” warned Li Yan. “We must remain vigilant, close the gaps in our cyber defenses, and treat every threat with the seriousness it deserves.”

